Executive Summary
SolarWinds published Trust Center advisories on 22 September 2026 for two unauthenticated remote code execution issues in SolarWinds Observability Self-Hosted (OSH) — the self-hosted observability product that runs on the SolarWinds Platform. The primary issue, CVE-2026-28324, is rated CVSS 3.1 9.8 Critical (network, low complexity, no privileges, no user interaction) and stems from insufficient integrity checks (CWE-345). A related issue, CVE-2026-28325, is rated CVSS 3.1 8.8 High (adjacent network) and involves deserialization of untrusted data (CWE-502) when a specific communication mode is configured.
Both vulnerabilities are fixed in Observability Self-Hosted 2026.2.3. As of 30 September 2026, neither CVE appears on the CISA Known Exploited Vulnerabilities (KEV) catalog, NVD lists both as Awaiting Analysis, and public reporting (including SecurityWeek) has not documented in-the-wild exploitation or a public proof-of-concept.
This advisory covers the vendor-published facts, version matrix, mitigations, and third-party risk implications when Observability Self-Hosted sits in customer, vendor, or MSP estates as a monitoring control plane.
Technical Information
CVE-2026-28324 (primary)
According to the SolarWinds Trust Center advisory and NVD/CVE records sourced from SolarWinds PSIRT:
- Issue: Unauthenticated remote code execution due to insufficient integrity checks (CWE-345 Insufficient Verification of Data Authenticity).
- Authentication: None required (PR:N).
- Attack vector: Network (AV:N); low attack complexity; no user interaction.
- Severity: CVSS 3.1 9.8 Critical —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. - Scope caveat (important): The vendor states the issue affects installations in a non-default and non-secure configuration. CVE product defaultStatus for this CVE is unaffected for the default/secure baseline. Exact configuration knobs are not named in the short Trust Center advisory text.
- Researcher credit: Kai Huang from Armadin.
- First published: 22 September 2026.
- CISA SSVC (Coordinator, recorded on NVD): exploitation none; automatable yes; technicalImpact total.
Vendor advisory: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28324
NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-28324
CVE-2026-28325 (related)
- Issue: Unauthenticated remote code execution from deserialization of untrusted data (CWE-502) when the product is configured to use a specific communication mode (mode not named in the short advisory body).
- Authentication: None required.
- Attack vector: Adjacent network (AV:A).
- Severity: CVSS 3.1 8.8 High —
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. - CVE defaultStatus: affected.
- Fixed build: Same as primary — 2026.2.3.
- CISA SSVC: exploitation none; automatable no; technicalImpact total.
Vendor advisory: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325
Product context (self-hosted, not SaaS-only cloud)
Observability Self-Hosted is a self-hosted / on-premises (and hybrid-capable) observability stack on the SolarWinds Platform. Secondary coverage (SecurityWeek) likewise describes on-prem/hybrid product framing. Release notes for 2026.2.3 list both CVEs under Fixed CVEs and include Web Performance Monitor (WPM) player critical-update guidance (passive/server-initiated vs active/player-initiated modes; post-upgrade password behavior). Vendor advisories do not explicitly map either CVE to the WPM player path alone; WPM context is included here only as release-note and documentation context for inventory and interim controls.
WPM documentation (contextual, not CVE-mapped by vendor): server-initiated default player port 17781; player-initiated port 17782.
Exploit / in-the-wild status
- No public PoC indexed as of 2026-09-30.
- SecurityWeek (24 September 2026) notes no mention of exploitation in the wild.
- CISA SSVC exploitation: none on both CVEs.
- CISA KEV: not listed (catalogVersion 2026.09.29, checked 2026-09-30).
Do not treat "not on KEV" as low priority: unauthenticated RCE against a monitoring control plane still warrants accelerated patch and exposure review.
Affected Product Versions
| Item | Detail | Source |
|---|---|---|
| Vendor | SolarWinds | Trust Center |
| Product | Observability Self-Hosted (OSH) on SolarWinds Platform (self-hosted) | Trust Center; release notes |
| Affected (vendor wording) | Observability Self-Hosted 2026.2.2 and below | CVE-2026-28324 / 28325 advisories |
| Affected (CVE affectedData) | Versions from 0 lessThan 2026.2.3 | NVD REST |
| Fixed | Observability Self-Hosted 2026.2.3 (release date 22 September 2026) | Trust Center; HCO 2026.2.3 release notes |
| CVE-2026-28324 config caveat | Non-default / non-secure configurations only; defaultStatus unaffected | Vendor; NVD/CVE |
| CVE-2026-28325 config caveat | When a specific communication mode is configured; defaultStatus affected | Vendor; NVD |
Inventory note (release notes): Flag WPM players with Enable Upgrade disabled — they may not auto-upgrade when 2026.2.3 is pushed. Post-upgrade, passive default players on the main polling engine switch to active (player-initiated); remote passive players receive a randomly generated strong password on auto-upgrade.
Detection helper (version check only): Tenable Nessus plugin 350168 (published 25 September 2026) flags OSH < 2026.2.3 for both CVEs.
Workaround and Mitigation
- Patch (primary): Upgrade SolarWinds Observability Self-Hosted to 2026.2.3 or later. Verify the running build, not only that an upgrade was initiated. Cover both CVE-2026-28324 and CVE-2026-28325 in the same patch window.
- Secure configuration: Follow the SolarWinds Platform secure configuration guidance. Do not expose the Platform website on the public Internet; apply network segmentation and firewall controls around management and observability interfaces.
- Interim communication hardening (aggregator / OpenCVE citing vendor docs): Configure a Player Password to secure communication between the WPM Player agent and the OSH server (see SolarWinds WPM "Add transaction locations" documentation). Exact CVE-to-mode mapping is not stated in the Trust Center advisory bodies — treat this as a sourced interim control, not a full substitute for 2026.2.3.
- Network restriction: Restrict inbound access to Observability / WPM player service ports to trusted hosts only. Documented WPM ports include 17781 (server-initiated) and 17782 (player-initiated).
- Post-upgrade WPM inventory: Confirm remote and default players upgraded; explicitly check players with Enable Upgrade disabled and remediate manually.
Release notes: https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
Secure configuration: https://documentation.solarwinds.com/en/success_center/orionplatform/content/core-secure-configuration.htm
Indicators of Compromise
None published in SolarWinds Trust Center advisories for CVE-2026-28324 or CVE-2026-28325, the NVD reference set, SecurityWeek coverage, or CISA KEV (CVEs not listed). No reputable primary or secondary source reviewed for this advisory maps these CVEs to specific MITRE ATT&CK technique IDs.
Do not invent hashes, IPs, domains, or ATT&CK IDs for this advisory.
Why this matters for third-party / vendor risk
SolarWinds Observability Self-Hosted is often the monitoring control plane for customer, supplier, and MSP estates — holding credentials, topology, configuration, and hybrid visibility into vendor-operated or shared infrastructure. An unauthenticated RCE path (even when limited to non-default/non-secure or specific communication modes) against that plane is a third-party risk event: ask every vendor or MSP that runs OSH / SolarWinds Platform with WPM for you whether they are on 2026.2.3+, whether management or WPM player ports are internet-reachable, and whether passive players or Enable-Upgrade-disabled agents remain unpatched.
Forwardable blurb for your TPRM / vendor-risk owner:
"Please confirm whether your organization (or any MSP operating on our behalf) runs SolarWinds Observability Self-Hosted / SolarWinds Platform with WPM at version below 2026.2.3, whether Observability or WPM player interfaces (including ports 17781/17782) are reachable from untrusted networks, and the patch date for 2026.2.3 addressing CVE-2026-28324 and CVE-2026-28325. Provide evidence of build version and compensating controls if patching is delayed."
Sources (selected)
- SolarWinds Trust Center — CVE-2026-28324: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28324
- SolarWinds Trust Center — CVE-2026-28325: https://www.solarwinds.com/trust-center/security-advisories/CVE-2026-28325
- SolarWinds Observability / HCO 2026.2.3 release notes: https://documentation.solarwinds.com/en/success_center/orionplatform/content/release_notes/hco_2026-2-3_release_notes.htm
- NVD REST CVE-2026-28324 / CVE-2026-28325 (Awaiting Analysis as of 2026-09-30)
- CISA KEV feed catalogVersion 2026.09.29 — neither CVE present (checked 2026-09-30)
- SecurityWeek (Ionut Arghire), 24 September 2026: https://www.securityweek.com/solarwinds-patches-critical-rce-flaws-in-observability-self-hosted/
- Tenable Nessus plugin 350168 (25 September 2026)
- SolarWinds Platform secure configuration / WPM add-location documentation



